Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3390 articles · 142067 vulns · 36/41 feeds (7d)
139,401 vulnerabilities total
9.8
cpanel · CVE-2026-41940 — WebPros cPanel and WHM Authentication Bypass via Login FlowKEVEXPLOITEDPATCHED
cpanel· CVSS 9.8· CWE-306
169🔥
20 art.
0
Apr 29, 2026
7.0
ivanti · CVE-2026-6973 — CVE-2026-6973: An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticKEVEXPLOITEDPATCHED
endpoint_manager_mobile· CVSS 7.0· CWE-20
142🔥
12 art.
0
May 7, 2026
9.8
ivanti · CVE-2026-1340 — CVE-2026-1340: A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.KEVEXPLOITEDPATCHED
endpoint_manager_mobile· CVSS 9.8· CWE-94
139🔥
8 art.
0
Jan 29, 2026
9.8
litellm · CVE-2026-42208 — LiteLLM: SQL injection in Proxy API key verificationKEVEXPLOITEDPATCHED
litellm· CVSS 9.8· CWE-89
129🔥
5 art.
0
Apr 24, 2026
7.8
linux · CVE-2026-31431 — crypto: algif_aead - Revert to operating out-of-placeKEVEXPLOITEDPATCHED
linux_kernel· CVSS 7.8· CWE-20
123🔥
66 art.
0
Apr 22, 2026
9.8
ivanti · CVE-2026-1281 — A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.KEVEXPLOITEDPATCHED
endpoint_manager_mobile· CVSS 9.8· CWE-94
111🔥
7 art.
0
Jan 29, 2026
10.0
facebook · CVE-2025-55182 — A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-KEVEXPLOITEDPATCHED
react· CVSS 10.0· CWE-502
97
17 art.
0
Dec 3, 2025
7.5
palo alto networks · CVE-2026-0300 — PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication PortalEXPLOITEDPATCHED
pan-os· CVSS 7.5· CWE-787
94
8 art.
0
May 6, 2026
8.8
linux · CVE-2026-43284 — xfrm: esp: avoid in-place decrypt on shared skb fragsEXPLOITEDPATCHED
linux_kernel· CVSS 8.8· CWE-20
89
17 art.
0
May 8, 2026
9.8
progress · CVE-2026-4670 — Improper Authentication vulnerability in Progress MOVEit AutomationEXPLOITEDPATCHED
moveit_automation· CVSS 9.8· CWE-305
89
10 art.
0
Apr 30, 2026
7.2
apache · CVE-2019-0193 — In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "daKEVEXPLOITEDPATCHED
solr· CVSS 7.2· CWE-94
88
1 art.
0
Aug 1, 2019
7.5
apache · CVE-2019-17558 — Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `veloKEVEXPLOITEDPATCHED
solr· CVSS 7.5· CWE-74
88
1 art.
0
Dec 30, 2019
9.8
go toolchain · CVE-2026-27143 — Missing bound checks can lead to memory corruption in safe Go in cmd/compileEXPLOITEDPATCHED
cmd/compile· CVSS 9.8
79
5 art.
0
Apr 8, 2026
9.1
spring · CVE-2026-40982 — CVE-2026-40982: Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server EXPLOITEDPATCHED
spring cloud config· CVSS 9.1· CWE-22
76
5 art.
0
May 7, 2026
7.7
progress · CVE-2026-5174 — Improper Access Control Vulnerability in Progress MOVEit AutomationEXPLOITEDPATCHED
moveit_automation· CVSS 7.7· CWE-20
74
8 art.
0
Apr 30, 2026
9.8
mozilla · CVE-2026-8091 — Incorrect boundary conditions in the Audio/Video: Playback componentEXPLOITEDPATCHED
firefox· CVSS 9.8
72
3 art.
0
May 7, 2026
8.8
google · CVE-2026-7896 — CVE-2026-7896: Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap EXPLOITEDPATCHED
chrome· CVSS 8.8· CWE-472
71
6 art.
0
May 6, 2026
5.3
axios · CVE-2026-42034 — Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0EXPLOITEDPATCHED
axios· CVSS 5.3· CWE-770
70
2 art.
0
Apr 24, 2026
7.5
golang · CVE-2026-32283 — Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tlsEXPLOITEDPATCHED
go· CVSS 7.5
69
5 art.
0
Apr 8, 2026
7.4
axios · CVE-2026-42035 — Axios: Header Injection via Prototype PollutionEXPLOITEDPATCHED
axios· CVSS 7.4· CWE-113
69
2 art.
0
Apr 24, 2026